Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://medium.com/%40nicatabbasov00002/open-redirect-vulnerability-62986ccaf0f7 | exploit |
https://github.com/corezoid/helm/issues/110 | issue tracking exploit |